Currently Being ModeratedJul 26, 2012 10:51 AM (in response to Frazzler)
I have the same problem after upgrading from Lion to Mountain Lion. What I did is open Keychain Access and grant the VPN certificate (the private key part) to allow for all applications to access.
Currently Being ModeratedJul 26, 2012 11:44 PM (in response to Frazzler)
I am a bit new at this. i use to have seemless VPN access to my work computer but when I upgraded to ML it all screwed up.
i use viscosity to for VPN and then Windows RDC to connect to my work computer. now when i connect through VISCOSITY it tells me that I am connected to my work server but when I try to use RDC it couldnt connect. at the same time while I am connected to VPN via Viscosity my internet stop working. I dont know what is going on but it is too frustrating for me.
anyways, can you please tell me how can I grant the VPN certificate (the private key part) to allow for all applications to access.
Currently Being ModeratedJul 27, 2012 1:49 AM (in response to Adnanm)
- Open Keychain Access (use spotlight), search for the certificate you use in your VPN configuration using the search box which is located in top right of the winddow, you may have to select the appropriate keychain from the list in the left hand navigation column titled 'Keychains', for me, mine was in the System keychain.
- You should see your certificate listed int he main window, it should have a small arrow to the left of the certificate name.
- Click on the arrow and this should reveal the private key below, it has a key icon associated with it.
- Double click on the private key and a window should pop up showing the private key.
- At the top of this window there are two buttons that can be toggled, 'Attributes' and 'Access Control', by default the Attributes button is selected (greyed out). Click on the 'Acces Control' button.
- The window changes to display a couple of butons, the top one 'Allow all applications to access this item' and 'Confirm before allowing access'. Click the top button 'Allow all applications to access this item'
- Click on the button 'Save Changes', you may have to enter your admin pasword.
- Close all the windows and quit Keychain Access.
- Now try your VPN.
- Good luck.
Currently Being ModeratedJul 27, 2012 2:16 PM (in response to Frazzler)
I'm experiencing the same issue on OSX 10.8 with certificates-based L2TP over IPsec VPN with MS-CHAPv2 for PPP, but the identified solution did not resolve the issue for me. /var/log/system.log shows the same as the OP. I've seen previous posters who had PPP issues using CHAP or PAP, but MS-CHAPv2 should "just work" OOB on the native client.
Currently Being ModeratedJul 27, 2012 3:34 PM (in response to 3g91ld3a)
I've been testing and determined the issue is definitely certificate related. Using PSK-based L2TP over IPsec with MS-CHAPv2 for PPP works just fine. However, the introduction of the certificate borks it. Any ideas?
Currently Being ModeratedJul 31, 2012 3:58 AM (in response to msltx)
The solution works indeed, but adds a security risk by allowing all application access to the private key. Better would be to _only_ allow the VPN client (racoon) access.
So instead of choosing the option "Allow all applications to access this item", you should use the option "Always allow access by these applications:" and select racoon. The path fo the executable is /usr/sbin/racoon.
Pro tip: if you don't see the /usr folder when browsing for the executable, use the Show hidden files shortcut: cmd-shift-. (cmd-shift-dot).
Currently Being ModeratedAug 2, 2012 1:59 AM (in response to Frazzler)
My problem with it. I can access VPN okay. However, when I then tried to access my organisations web pages it will not load. Other web pages are ok. The problem is the same no matter I am on the internal network or coming in from outside the network. When I turn VPN off it is OK. I use the built in VPN in Mountain Lion. The previous OS was fine.
Currently Being ModeratedAug 2, 2012 4:01 PM (in response to Frazzler)
As I said my VPN connection works fine -- It shows I am connected, but consequently I can not then access the actual organization's web site. Web pages are hosted in the organization - www.cdu.edu.au
Currently Being ModeratedAug 6, 2012 2:17 AM (in response to Frazzler)
I have the same problem, but my case is a bit different, since my certificates do not show on the Keychain Access. They are stored in /private/etc/cert.
Any idea How I could solve that problem in this case?